Evil Twin Attacks
Wireless networks are vulnerable to evil twin attacks, where an attacker deploys a rogue access point (AP) that mimics a legitimate one to intercept traffic, steal credentials, or launch further attacks. This section explains how such attacks operate, how to detect them, and strategies to mitigate their impact.
Mechanics of an Evil Twin Attack¶
An evil twin attack typically follows these steps:
1. Reconnaissance: The attacker identifies a target AP (e.g., a corporate Wi-Fi network) and notes its SSID, BSSID (MAC address), and security protocols.
2. Deployment: The attacker sets up a rogue AP with the same SSID and, if possible, the same BSSID. This AP often uses the same encryption (e.g., WPA2-PSK) to appear legitimate.
3. Luring Victims: The attacker may broadcast the fake AP on the same channel as the target to trick users into connecting. Techniques like deauthentication attacks (e.g., using aireplay-ng) can force users to disconnect from the real AP.
4. Traffic Interception: Once connected, the attacker captures data (e.g., HTTP traffic, credentials) using packet sniffing tools like Wireshark or tcpdump.
Example:
Detecting Evil Twin APs¶
Detection requires proactive monitoring and network analysis:
1. SSID and BSSID Monitoring: Use tools like airodump-ng to track unexpected APs with matching SSIDs or spoofed BSSIDs.
2. DHCP and ARP Anomalies: Monitor for rogue DHCP servers or ARP spoofing using tools like tcpdump:
Prevention Strategies¶
To mitigate evil twin attacks, adopt the following measures: 1. Dynamic SSID Rotation: Regularly change SSIDs to reduce the likelihood of spoofing. Use unique BSSIDs for each AP. 2. 802.1X Authentication: Enforce EAP methods (e.g., EAP-TLS) to require client certificates, making it harder for attackers to impersonate users. 3. MAC Address Filtering: Block unauthorized devices from connecting, though this can be bypassed with MAC spoofing. 4. Wireless Intrusion Detection Systems (WIDS): Deploy systems like Cisco Stealthwatch or Aruba ClearPass to automatically detect and alert on rogue APs. 5. User Education: Train users to verify network credentials and avoid connecting to unknown networks.
Example:
Configure a firewall to block traffic to the evil twin's IP address:
Key takeaways¶
- Evil twin attacks rely on mimicking legitimate APs to intercept traffic, requiring vigilant monitoring and network segmentation.
- Detection involves analyzing SSID/BSSID anomalies, DHCP/ARP traffic, and client behavior.
- Prevention includes dynamic SSID rotation, 802.1X authentication, WIDS, and user education to reduce attack surface.
- Tools like
airodump-ngandtcpdumpare critical for both attack simulation and defense analysis.